SB20260919151 - Off-by-one in Linux kernel soc
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-90068)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read memory out of bounds.
The vulnerability exists due to an off-by-one error in snd_soc_dapm_put_enum_double() when writing a second enum channel value. A local user can set the second enum channel value equal to the number of enum items to read one element past the end of the value table.
The affected adav80x control reports two values, and core input validation is disabled by default.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/10a36512c21f861a03fba461a7ead09023df9c1b
- https://git.kernel.org/stable/c/14511c9b54ceeeef487409d73947c89ee8563590
- https://git.kernel.org/stable/c/32fc048391112559c34cb88d13594546939a4cd6
- https://git.kernel.org/stable/c/496081b4edc1f6e662418831c5b14cddd8d7920c
- https://git.kernel.org/stable/c/55126ef66298e43c69f192acebae8c7cc0022cf6
- https://git.kernel.org/stable/c/57ab955bde747327fb2042516ae1b7192c30e881
- https://git.kernel.org/stable/c/806fa4e1f2bf73c54bc4b6360790ecc69d095ca5
- https://git.kernel.org/stable/c/faf539af1a595a26e5a081a4e512caee2bc2f4c5